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DETAILED ACTION 

1 . Claims 1-35 are pending in this office action. 

Acknowledges 

2. Receipt is acknowledged of the following items: 

o Information Disclosure Statement (IDS) filed on 01/03/2002 and made of record 
as Paper No. 3. The references cited on the PTOL 1449 form have been 
considered. 



Claim Rejections - 35 USC § 112 

The following is a quotation of the second paragraph of 35 U.S.C. 1 12: 

The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the 
subject matter which the applicant regards as his invention. 

3. Claims 7-9 and 23-25 are rejected under 35 U.S.C. 112, second paragraph, as being 
indefinite for failing to particularly point out and distinctly claim the subject matter which 
applicant regards as the invention. 

Regarding claims 7-8, and 23-24, there is insufficient antecedent basis for "first entity 55 in 
the claim. No "first entity 55 is introduced in the base claim. 

Regarding claims 9 and 25, there is insufficient antecedent basis for "privileges 55 in the 

claim. 
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Claim Rejections - 35 USC §102 

The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 
A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public use or on 
sale in this country, more than one year prior to the date of application for patent in the United States. 

4. Claims 1-14, 16-30, and 32-35 are rejected under 35 U.S.C. 102(b) as being anticipated 
by Glasser (US 5,956,715). 

Regarding claims 1,17, and 33, Glasser discloses a method, an apparatus and a computer 
program product for administering managed resources, comprising: defining a set of privileges 
for a managed resource; and attaching an access control list to an object that represents the 
managed resource, wherein the access control list assigns at least one privilege from the set of 
privileges to an entity. See Col. 1, lines 54-58, col. 4, lines 36-65, and col. 7, lines 5-12. 

Regarding claims 6, 22, and 34, Glasser discloses a method for administering a plurality 
of managed resources including at least one first level resource and at least one second level 
resource, wherein each of the at least one second level resource is a subresource of a first level 
resource (See Fig. 4, and col. 6, line 55 to col. 7, line 11) comprising: 

o defining a first set of permissions for the at least one first level resource (See Col. 
7, lines 7-10); and 

o attaching a first access control list to a first object that represents a first managed 
resource, wherein the first managed resource is a first level resource and the first 
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access control list controls access to the first managed resource and at least one 
subresource of the first managed resource based on the first set of permissions 
(See col. 7, lines 5-27). 

Regarding claims 1 1, 27, and 35, Glasser discloses a method for administering managed 
resources, comprising: 

o receiving a request from a user to perform an operation on a managed resource 

(See col. 9, line 58 to col. 10, line 3); 
o finding an access control list corresponding to the managed resource (See col. 10, 
lines 4-14); and 

o determining whether the operation is permitted for the user based on the access 
control list (See col. 10, lines 15-29). 
See also col. 10, lines 48-67. 

Regarding claims 2-3, 7-8, 18-19, and 23-24, Glasser discloses the entity is an individual 
user/a group of users (See Col. 7, lines 5-12). 

Regarding claims 4 and 20, Glasser discloses the managed resource is one of a plurality 
of managed resources arranged in a hierarchy (See Fig. 4, for example, and Col. 3, lines 1- 10). 

Regarding claims 5, 9, 21, and 25, Glasser discloses the set of privileges comprises a set 
of operations that may be performed for the managed resource (See col. 4, lines 43-49). 
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Regarding claims 10 and 26, Glasser discloses defining a second set of permissions for a 
second managed resource; and attaching a second access control list to a second object that 
represents the second managed resource, wherein the second access control list controls access to 
the second managed resource and at least one subresource of the second managed resource based 
on the second set of permissions (See col. 7, lines 5-40). 

Regarding claims 12 and 28, Glasser discloses the managed resource is one of a plurality 
of managed resources arranged in a hierarchy and wherein the step of finding an access control 
list comprises searching the hierarchy for an access control list which is attached closest to the 
managed resource (See col. 10, lines 4-29). 

Regarding claims 13 and 29, Glasser discloses the step of finding an access control list 
comprises finding a first access control list that assigns a first permission for the user and a 
second access control list that assigns a second permission for the user (See col. 10, lines 15-29). 

Regarding claims 14 and 30, Glasser discloses the step of determining whether the 
operation is permitted for the use comprises selecting the access control list, from the first access 
control list and the second access control list, with a permission that more specifically matches 
the user (See col. 10, lines 15-29). 
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Regarding claims 16 and 32, Glasser discloses the method is performed by an 



authorization server (server 120, Fig. 1). 



Claim Rejections - 35 USC§ 103 



The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

5. Claims 15 and 31 are rejected under 35 U.S.C. 103(a) as being unpatentable over Glasser 
(US 5,956,715), in view of Abadi (US 5,315,657). 

Regarding claims 15 and 31, Glasser discloses all the claimed subject matter as set forth 
above. Glasser teaches the first permission identifies a first set of operations permitted for the 
user and the second permission identifies a second set of operations permitted for the user (See 
col. 8, lines 17-26, Glass et al.). However, Glasser is silent as to determining whether the 
operation is permitted for the user comprises performing an OR operation on the first set of 
operations and the second set of operations. On the other hand, Abadi teaches performing an OR 
(UNION) operation on two sets of operations (See Fig. 10, and col. 18, lines 22-58, Abadi et al.). 
It would have been obvious to one having ordinary skill in the art at the time the invention was 
made to incorporate Abadi 5 s access right expressions (such as OR operation) onto the first set 
and the second set of operations of Glasser so that permissions is correctly determined for the 
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specific user. The motivation would have been to enable the system to perform accurate 
computing of the user's permissions when the user belongs to more than one group of resources. 

Conclusion 

6. The prior art made of record and not relied upon is considered pertinent to applicant's 
disclosure. 

Lewis U.S Patent No. 6,233,576 discloses enhanced security for computer system 
resources with a resource access authorization control facility that creates files and provides 
increased granularity of resource permission. 

Win U.S Patent No. 6,453,353 discloses role-based navigation of information resources. 

Fabbio U.S Patent No. 5,335,346 discloses access control policies for an object oriented 
database, including access control lists which span across object boundaries. 

7. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Merilyn P Nguyen whose telephone number is 703-305-5177. 
The examiner can normally be reached on M-F: 8:30 - 5:00. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Safet Metjahic can be reached on 703-308-1436. The fax phone numbers for the 
organization where this application or proceeding is assigned are 703-872-9306 for regular 
communications and 703-746-7240 for After Final communications. 

Any inquiry of a general nature or relating to the status of this application or proceeding 
should be directed to the receptionist whose telephone number is 703-305-3900. 
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